CAP - A Context-Aware Framework for Detection and Analysis of Packed Malware
Muhammad Nouman Ahmed, Zafar Iqbal, Hassan Mahmood, Moiz Abdullah · 2024
The widespread use of packers to obfuscate and shield executable files makes it difficult for malware analysts to identify and analyze malicious samples. As packers implement more complex protective measures, developing advanced detection and analysis methods is crucial to stay ahead of cyber threats. This research is motivated by the requirement to examine the effectiveness of four well-known techniques: PEID Signatures, Import Hashing, Fuzzy Hashing, and Automatic YARA Signatures, which go beyond standard obfuscation defences. A dataset containing 3,089 samples, which consisted of 25 different packers, was collected. The best accuracy was obtained using a context-aware approach that included the findings from all four scripts, resulting in an astounding 96% detection rate. Using the proposed methods, packed malware samples can be detected more reliably. Moreover, a malware analyst can identify packed malware with minimal effort.